IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-28509 HIGH 7.5 rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. 0.3% —
CVE-2023-28302 HIGH 7.5 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 92.6% —
CVE-2023-28300 HIGH 7.5 microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability 1.0% —
CVE-2023-28247 HIGH 7.5 microsoft windows_server_2012 Windows Network File System Information Disclosure Vulnerability 1.6% —
CVE-2023-28241 HIGH 7.5 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability 2.0% —
CVE-2023-28238 HIGH 7.5 microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability 0.9% —
CVE-2023-28234 HIGH 7.5 microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability 1.7% —
CVE-2023-28233 HIGH 7.5 microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability 1.7% —
CVE-2023-28232 HIGH 7.5 microsoft windows_10_1507 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 0.9% —
CVE-2023-28227 HIGH 7.5 microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability 6.6% —
CVE-2023-28217 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 1.9% —
CVE-2023-27875 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. 0.6% —
CVE-2023-27871 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. 0.9% —
CVE-2023-27730 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. 0.7% —
CVE-2023-27729 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. 0.7% —
CVE-2023-27728 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. 0.7% —
CVE-2023-27727 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. 0.7% —
CVE-2023-27522 HIGH 7.5 apache http_server HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. 2.1% —
CVE-2023-27378 HIGH 7.5 f5 big-ip_access_policy_manager Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached 0.4% —
CVE-2023-26513 HIGH 7.5 apache sling_resource_merger Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. 1.5% —
CVE-2023-26464 HIGH 7.5 apache log4j ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on w 1.9% —
CVE-2023-26031 HIGH 7.5 apache hadoop Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root p 2.1% —
CVE-2023-26021 HIGH 7.5 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864. 1.0% —
CVE-2023-25956 HIGH 7.5 apache apache-airflow-providers-amazon Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1. 1.5% —
CVE-2023-25692 HIGH 7.5 apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. 1.8% —